The Ugly‘s side: Why compliance isn‘t what you think

The role of compliance demonstrated on the Ugly in the tale of cybersecurity.

By José Francisco Agulló (ERNI Spain)

Compliance often plays the villain in cybersecurity: policies, audits and awkward questions nobody enjoys. But behind the checklists is experience that was earned the hard way. This article gives the Ugly a voice and shows why compliance is not about control, but about protecting people, products and trust.

Yes, I’m the Ugly – And I want you to understand why

You know the type. The person with the checklist, talking ISO 27001, NIS2, GDPR, CRA and more. The compliance officer sidestepped by tech teams, the risk manager who asks awkward questions. I’m not at the fun brainstorming sessions, but I’m in your thoughts when things go wrong.

I get how I seem: a necessary hassle, not a cool teammate. You may remember all those audit controls I mention over and over again. They come from seeing what happens without them.

Asking for proof of encryption keeps data safe. Access reviews prevent small mistakes from becoming big problems. I just want to help turn “we probably should” into something solid. It can feel tough, but it’s there to support everyone.

I understand the looks

I see it when I share a new policy: that quiet sigh, “Do we really need this now?”

  • Developers wonder if input validation can wait until after launch
  • Management feels MFA (Multifactor Authentification) slows down the day
  • Business thinks the certificate means we’re covered

I live this too. Weeks spent on risk assessments and control checks, hoping it sticks, only to see shortcuts later because “we already passed the audit.” I understand the frustration. But this work is about protecting what we all care about.

What I’ve learned from the hard moments

I don’t bring this up to make life harder. I’ve seen the other side:

  • A missed input check that lets in bad data in and harms customers
  • A delayed patch leading to hours of recovery work
  • A vendor trusted without safeguards, pulling everyone down

Compliance is like that extra check you do without thinking – locking the door twice, even on a quiet street. It’s the developer refreshing API keys just in case. The sysadmin reviewing logs on a weekend. Quiet habits that keep things steady.

Collective responsibility ahead

This isn’t just my job – it’s everyone’s. Every team member – not just audit attendees – needs to question assumptions, spot anomalies and choose risk awareness over shortcuts. Certified companies keep getting hit, but we don’t have to be next. Think two steps ahead, ask for evidence behind every claim. Certificates win clients, but mindsets stop breaches.

Let’s talk about it

Next time you spot the Ugly coming with questions, I hope you’ll see a partner, not a roadblock. Ask me the ‘why’ behind it. Share your side. Together, we make things stronger. Because at the end of the day, this isn’t about rules – it’s about keeping what we’ve built safe for tomorrow.

Are you ready
for the digital tomorrow?
better ask ERNI

We empower people and businesses through innovation in software-based products and services.